home.social

#securitychaosengineering — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securitychaosengineering, aggregated by home.social.

fetched live
  1. Want to watch a video that makes lessons from Kelly Shortridge and Aaron Rinehart's "Security Chaos Engineering" book sink in? This video by Kyle Hill on the Three Mile Island disaster is it. Learn what a "Normal Accident" is. Bonus: it's an entertaining video about a misunderstood nuclear disaster. youtu.be/cL9PsCLJpAA?si=zHf6FE

    @shortridge #ChaosEngineering #SecurityChaosEngineering #InfoSec

  2. Want to watch a video that makes lessons from Kelly Shortridge and Aaron Rinehart's "Security Chaos Engineering" book sink in? This video by Kyle Hill on the Three Mile Island disaster is it. Learn what a "Normal Accident" is. Bonus: it's an entertaining video about a misunderstood nuclear disaster. youtu.be/cL9PsCLJpAA?si=zHf6FE

    @shortridge #ChaosEngineering #SecurityChaosEngineering #InfoSec

  3. i am looking forward to this webinar with Kennedy Torkura, to discuss cloud security and security chaos engineering. Kennedy and I chat regularly and that has been so fun we thought we let you in on the conversation.

    Join us Oct 17th

    #cloudsecurity #securitychaosengineering #cybersecurity
    mitigant.io/webinar/innovating

  4. i am looking forward to this webinar with Kennedy Torkura, to discuss cloud security and security chaos engineering. Kennedy and I chat regularly and that has been so fun we thought we let you in on the conversation.

    Join us Oct 17th

    #cloudsecurity #securitychaosengineering #cybersecurity
    mitigant.io/webinar/innovating

  5. just finished #SecurityChaosEngineering (the book)

    review blog coming soon but in the meantime, go get it

    kellyshortridge.com/book.html

    Euros tell me it is getting released May 16 over there

  6. just finished #SecurityChaosEngineering (the book)

    review blog coming soon but in the meantime, go get it

    kellyshortridge.com/book.html

    Euros tell me it is getting released May 16 over there

  7. #SecurityChaosEngineering is filled with gems like this:

    Despite the empirical evidence, infosec folk wisdom says that descriptive error messages are pestiferous because attackers can learn things from the message that assist their operation. Sure, and using the internet facilitates attacks - should we avoid it too?

  8. #SecurityChaosEngineering is filled with gems like this:

    Despite the empirical evidence, infosec folk wisdom says that descriptive error messages are pestiferous because attackers can learn things from the message that assist their operation. Sure, and using the internet facilitates attacks - should we avoid it too?

  9. I had a blast at AWS Summit Berlin last week. Here are my impressions about the event, which was a unique experience in many aspects for me, and surprisingly intimate and local

    #cloudsecurity #securitychaosengineering

    linkedin.com/pulse/very-europe

  10. I had a blast at AWS Summit Berlin last week. Here are my impressions about the event, which was a unique experience in many aspects for me, and surprisingly intimate and local

    #cloudsecurity #securitychaosengineering

    linkedin.com/pulse/very-europe

  11. one of my go-to phrases is:

    #cloudsecurity and secure #CloudTransformation is 2% tooling, 3% skills, 5% talent and 90% organizational drama

    i therefore love this following quote:

    Any computer system is inherently sociotechnical - humans design, build and operate them. our architectures must reflect that. With advances in hardware, and innovation like infrastructure-as-a-service, the emerging (but not yet dominant) trend is for a system's computer costs to represent a smaller portion of budget than the cost of the engineers who build and maintain the system (...)

    Beyond costs, organizational design strongly influences system design (and we suspect vice versa as well). Conway's Law, which states that organizations design systems that mirror their own communication structures, is difficult to fight. When designing a system and allocating your Effort Investment Portfolio, it's important to consider not only the system architecture, but also the structure of the teams that would build, operate, and use the system.

    #SecurityChaosEngineering

  12. one of my go-to phrases is:

    #cloudsecurity and secure #CloudTransformation is 2% tooling, 3% skills, 5% talent and 90% organizational drama

    i therefore love this following quote:

    Any computer system is inherently sociotechnical - humans design, build and operate them. our architectures must reflect that. With advances in hardware, and innovation like infrastructure-as-a-service, the emerging (but not yet dominant) trend is for a system's computer costs to represent a smaller portion of budget than the cost of the engineers who build and maintain the system (...)

    Beyond costs, organizational design strongly influences system design (and we suspect vice versa as well). Conway's Law, which states that organizations design systems that mirror their own communication structures, is difficult to fight. When designing a system and allocating your Effort Investment Portfolio, it's important to consider not only the system architecture, but also the structure of the teams that would build, operate, and use the system.

    #SecurityChaosEngineering

  13. [...] SCE is all about outcomes rather than output, prefers psychological safety to ruling with an iron fist, and experiments with strategies optimized for the real world, noy an ideal security-is-the-only-priority world. The simple premise of achieving tangible outcomes rather than performing dramatic motions to give the appearance of "doing something" should be compelling to all stakeholders involved in an organization's security - from the security teams themselves to software engineering and product teams (not to mention company leadership who can start to see more tangible outcomes from the security budget).

    #SecurityChaosEngineering

  14. [...] SCE is all about outcomes rather than output, prefers psychological safety to ruling with an iron fist, and experiments with strategies optimized for the real world, noy an ideal security-is-the-only-priority world. The simple premise of achieving tangible outcomes rather than performing dramatic motions to give the appearance of "doing something" should be compelling to all stakeholders involved in an organization's security - from the security teams themselves to software engineering and product teams (not to mention company leadership who can start to see more tangible outcomes from the security budget).

    #SecurityChaosEngineering

  15. If you optimize for eliminating failure, you won't be taken seriously in business settings where the clear goal is to make more money (...). Eliminating failure costs money, but introducing change - by shipping features, launching products, and other activities - makes money. Attempting to eliminate failure often costs more money than the amount lost by the failure itself. Actively investing in change is a competitive advantage; a focus on eliminating failure chokes innovation, corroding that advantage. [...]

    In contrast, a security program with the safe-to-fail mindset can accept surprises, minimize their impact, and learn from them. It acknowledges the world is absurd and can cope with reality not being a fairy tale with easily defined and enforced "good" and "evil".

    #SecurityChaosEngineering

  16. If you optimize for eliminating failure, you won't be taken seriously in business settings where the clear goal is to make more money (...). Eliminating failure costs money, but introducing change - by shipping features, launching products, and other activities - makes money. Attempting to eliminate failure often costs more money than the amount lost by the failure itself. Actively investing in change is a competitive advantage; a focus on eliminating failure chokes innovation, corroding that advantage. [...]

    In contrast, a security program with the safe-to-fail mindset can accept surprises, minimize their impact, and learn from them. It acknowledges the world is absurd and can cope with reality not being a fairy tale with easily defined and enforced "good" and "evil".

    #SecurityChaosEngineering

  17. We can characterize the security status quo as the "fail-safe" mindset, reflective of a prevention-driven approach. The status quo in cybersecurity is to stamp out all possible vulnerabilities, "risks" or "threats" before they happen. [...] this is impossible - and a rather profligate use of an organization's resources, The "fail-safe" logic leads to a false sense of security. It does not care how the system failed or how it recovered from failure, but demonizes that it failed at all.

    If we shift towards a "safe-to-fail" logic, we transform towards preparation - anticipating failures and investing effort in preparing to recover and adapt to them. Safe-to-fail seeks to understand how systems respond to adverse, changing conditions and how they fail in certain scenarios. Does the system recover with speed and grace? Are critical functions affected, or just noncritical ones?

    #SecurityChaosEngineering

  18. We can characterize the security status quo as the "fail-safe" mindset, reflective of a prevention-driven approach. The status quo in cybersecurity is to stamp out all possible vulnerabilities, "risks" or "threats" before they happen. [...] this is impossible - and a rather profligate use of an organization's resources, The "fail-safe" logic leads to a false sense of security. It does not care how the system failed or how it recovered from failure, but demonizes that it failed at all.

    If we shift towards a "safe-to-fail" logic, we transform towards preparation - anticipating failures and investing effort in preparing to recover and adapt to them. Safe-to-fail seeks to understand how systems respond to adverse, changing conditions and how they fail in certain scenarios. Does the system recover with speed and grace? Are critical functions affected, or just noncritical ones?

    #SecurityChaosEngineering

  19. ... for most organizations, building your defenses to a level where attackers are forced to use zero days will restrict the spectrum of potential attackers, and attacker actions, to only those who are the best resourced and experienced, such as nation-state actors

    :1000:​

    there is so much we can do before we have to entertain the esoteric and unlikely. if we force our adversaries to pull out 0days, we have raised the costs considerably.

    Having just read This is how they tell me the world ends by Nicole Perlroth, showing how the market for weaponized, reliable 0days now runs in the millions of dollars, this is even more pertinent. And good detections and resilience could help 1) identify the vulnerability, and 2) reduce the impact blast radius and thus further raise the cost to the attacker

    #SecurityChaosEngineering

  20. ... for most organizations, building your defenses to a level where attackers are forced to use zero days will restrict the spectrum of potential attackers, and attacker actions, to only those who are the best resourced and experienced, such as nation-state actors

    :1000:​

    there is so much we can do before we have to entertain the esoteric and unlikely. if we force our adversaries to pull out 0days, we have raised the costs considerably.

    Having just read This is how they tell me the world ends by Nicole Perlroth, showing how the market for weaponized, reliable 0days now runs in the millions of dollars, this is even more pertinent. And good detections and resilience could help 1) identify the vulnerability, and 2) reduce the impact blast radius and thus further raise the cost to the attacker

    #SecurityChaosEngineering

  21. as someone who has been talking about "attacker ROI" for about a decade, i think this is just a brilliant formulation for our current CI/CD age:

    ... it's best to think about attacks as having their own lifecycle (i.e. the Attack Development Lifecycle, or ADLC). Attackers will maintain a feedback loop of persisting, expanding access, exfiltrating information, and using the information to polish persistence, expand access, and so forth (if there were a Gartner for attackers, it might be labeled Continuous Persistence/Continuous Expansion, or CP/CE for short). Disrupting that feedback loop or poisoning it can be invaluable.

    [emphasis mine]

    #SecurityChaosEngineering

  22. as someone who has been talking about "attacker ROI" for about a decade, i think this is just a brilliant formulation for our current CI/CD age:

    ... it's best to think about attacks as having their own lifecycle (i.e. the Attack Development Lifecycle, or ADLC). Attackers will maintain a feedback loop of persisting, expanding access, exfiltrating information, and using the information to polish persistence, expand access, and so forth (if there were a Gartner for attackers, it might be labeled Continuous Persistence/Continuous Expansion, or CP/CE for short). Disrupting that feedback loop or poisoning it can be invaluable.

    [emphasis mine]

    #SecurityChaosEngineering

  23. Because we live in this indeterministic reality we must preserve an openness to evolution and disregard the rigidness that status quo security approaches recommend. Building upon the feedback loops and learning culture ..., we must continue learning about our systems and tracking results of our experiments and outcomes of incidents to refine our understanding of what a truly resilient security program looks like for our systems.

    #SecurityChaosEngineering

  24. Because we live in this indeterministic reality we must preserve an openness to evolution and disregard the rigidness that status quo security approaches recommend. Building upon the feedback loops and learning culture ..., we must continue learning about our systems and tracking results of our experiments and outcomes of incidents to refine our understanding of what a truly resilient security program looks like for our systems.

    #SecurityChaosEngineering

  25. absolute gold. 🤩​

    We, as stakeholders who wish to keep our systems safe, also need to be open to change within ourselves (not just in our machines). We might be wedded to the status quo or we may not want to change course because we've already invested so much time and money. Maybe something was our special idea that got us a promotion. Or maybe we're worried that change might be hard.

    But this cognitive resistance will erode our system's ability to respond and adapt to incidents. A good decision a year ago might not be a good decision today; we need to be vigilant for when our assumptions no longer ring true based on how the world around us has changed.

    @shortridge #SecurityChaosEngineering

  26. absolute gold. 🤩​

    We, as stakeholders who wish to keep our systems safe, also need to be open to change within ourselves (not just in our machines). We might be wedded to the status quo or we may not want to change course because we've already invested so much time and money. Maybe something was our special idea that got us a promotion. Or maybe we're worried that change might be hard.

    But this cognitive resistance will erode our system's ability to respond and adapt to incidents. A good decision a year ago might not be a good decision today; we need to be vigilant for when our assumptions no longer ring true based on how the world around us has changed.

    @shortridge #SecurityChaosEngineering